Vulnerability in PRISMAproduction CVE-2026-3245

Description

A deserialization vulnerability has been identified in PRISMAproduction.  This vulnerability could allow an unauthenticated attacker on an adjacent network to execute arbitrary code.

Affected Product

PRISMAproduction Version 6.5 or earlier.

CVE/CVSS

CVE-2026-3245: A deserialization vulnerability in PRISMAproduction that may lead to arbitrary code execution.

CVSS v4 CVSS: 4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Base Score: 7.7
CVSS v3 CVSS: 3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score: 7.5

Remediation

A fix patch (Version 6.5.1 or higher) is available.  Installation of the patch requires assistance from Service & Support personnel.  Please contact your local or regional Canon Service & Support representative to arrange installation.

Thank you to Anton Fabricius and Moritz Bechler of SySS GmbH for reporting this vulnerability.